# Reading files dynamically and using computer hardware

**URL:** <https://community.zeek.org/t/reading-files-dynamically-and-using-computer-hardware/5347>\
**Category:** Zeek\
**Created:** [June 9, 2018, 3:13am UTC](https://community.zeek.org/t/reading-files-dynamically-and-using-computer-hardware/5347 "2018-06-09T03:13:15Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Joseph\_Gresham](https://avatars.discourse-cdn.com/v4/letter/j/f6c823/32.png) [@Joseph\_Gresham](https://community.zeek.org/u/Joseph_Gresham)\
**Post date:** [June 9, 2018, 3:13am UTC](https://community.zeek.org/t/reading-files-dynamically-and-using-computer-hardware/5347/1 "2018-06-09T03:13:15Z")

</div>

I would direct you to :

[http://mailman.icsi.berkeley.edu/pipermail/bro/2018-January/012804.html](http://mailman.icsi.berkeley.edu/pipermail/bro/2018-January/012804.html)

I use a pipeline based on pcapdj + pcapsplitter from the PcapPlusPlus  
toolkit (both on github).

Previously I used tcpsplit (also on github) but found pcapsplitter to  
have better performance and better treatment of non tcp flows.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:45pm UTC](https://community.zeek.org/t/reading-files-dynamically-and-using-computer-hardware/5347/2 "2022-05-06T15:45:52Z")

</div>


